Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

132 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.36%—Supsystic Popup15/4/202417/6/2026
Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27.
AplazadaMedia (4.3)0.21%—Supsystic Digital PublicationsAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7.
AplazadaMedia (4.3)0.20%—Supsystic Ultimate MapsAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Ultimate Maps by Supsystic.This issue affects Ultimate Maps by Supsystic: from n/a through 1.2.16.
ModificadaAlta (8.8)0.23%—Supsystic Easy Google Maps12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps.This issue affects Easy Google Maps: from n/a through 1.11.11.
AplazadaMedia (5.9)0.36%—Supsystic SliderAI29/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic Slider by Supsystic allows Stored XSS.This issue affects Slider by Supsystic: from n/a through 1.8.10.
AplazadaAlta (7.6)0.55%—Slider BY SupsysticAI28/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Supsystic Slider by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.10.
ModificadaMedia (4.8)0.34%—Supsystic Photo Gallery27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Photo Gallery by Supsystic gallery-by-supsystic.This issue affects Photo Gallery by Supsystic: from n/a through <= 1.15.16.
ModificadaMedia (4.8)0.42%—Supsystic Ultimate Maps16/1/202417/6/2026
The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (5.4)0.29%—Synopsys Seeker9/1/202417/6/2026
Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a specially crafted payload.
ModificadaMedia (6.5)0.52%—Phpsysinfo19/12/202317/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive information via a crafted page in the XML.php file.
ModificadaMedia (4.8)0.39%—Supsystic Gdpr Cookie Consent15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic GDPR Cookie Consent by Supsystic allows Stored XSS.This issue affects GDPR Cookie Consent by Supsystic: from n/a through 2.1.2.
ModificadaAlta (8.8)0.27%—Digital Publications BY Supsystic9/12/202317/6/2026
The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged…
ModificadaAlta (8.8)0.21%—Supsystic Contact Form12/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Contact Form by Supsystic plugin <= 1.7.27 versions.
ModificadaCrítica (9.8)1.5%—Supsystic Popup17/7/202317/6/2026
The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.
ModificadaMedia (5.4)0.28%—Supsystic Easy Google Maps9/6/202317/6/2026
The Easy Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.11.7. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to executes AJAX actions via a forged request granted…
ModificadaAlta (8.8)0.25%—Supsystic Easy Google Maps28/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps plugin <= 1.11.7 versions.
ModificadaAlta (8.8)0.27%—Supsystic Coming Soon22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Coming Soon by Supsystic plugin <= 1.7.10 versions.
ModificadaAlta (8.8)0.32%—Supsystic Contact Form17/5/202317/6/2026
The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.24. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged request…
ModificadaAlta (7.2)0.70%—Apsystems Alternergy Power Control Software11/5/202317/6/2026
Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the component /models/management_model.php.
ModificadaCrítica (9.8)0.62%—Synopsys Code DX27/4/202317/6/2026
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating the token. A malicious actor who…
ModificadaMedia (5.3)0.43%—Synopsys Coverity29/3/202317/6/2026
Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are…
AnalizadaCrítica (9.8)2.7%⚠ Explotación activaHelpsystems Cobalt Strike24/3/202317/6/2026
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
ModificadaCrítica (9.8)85%💥 ExploitApsystems Energy Communication Unit Firmware14/3/202317/6/2026
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.
ModificadaAlta (8.8)0.28%—Supsystic Slider14/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Slider by Supsystic plugin <= 1.8.5 versions.
ModificadaMedia (4.3)0.51%—Jenkins Synopsys Coverity15/2/202317/6/2026
A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Orbitaley — Vulnerabilidades